For licensed Collaborators with permission for this task. Check the selected organisation; feature availability and record access still apply.
What you will achieve
Describe one processing activity, connect its data and people, and make gaps visible for review. RoPA means Record of Processing Activities.
Before you start
Speak to the people who run the activity. Gather its purpose, team, data inputs and outputs, affected people, recipients, retention and safeguards. Obtain the responsible privacy owner's conclusions where legal judgement is needed.
Describe a real activity, such as handling recruitment applications, rather than naming an entire department without a clear processing scope.
Create the record
- Open the RoPA catalogue and choose its create action.
- In Create New RoPA Entry, enter the activity name, Team and purpose.
- Select the applicable legal basis, processing type and organisation role from the available choices. Record the agreed basis; do not select an answer merely to fill a required field.
- Link relevant Business Capabilities, Source Data Entities, Output Data Entities and Data Subjects.
- Record retention and the actual facts about international transfers, processors and special-category data. Where transfer fields appear, use the verified destination and safeguard information.
- Describe the security measures and select Create RoPA.
Complete the working record
Open Narrative to explain how the activity operates in plain language. Review Data flow and relationships against the actual process; linked records should describe the same activity.
In Legal Compliance, inspect legal basis, retention, notices and rights coverage. The interface can show inherited rights and an Override for this activity action. Make an override only for an approved, recorded reason.
Review linked assessments, controls, risks and documentation. Use the overview's Readiness breakdown to find incomplete evidence, following each issue to its owning area.
Check it worked
Reload the record and ask the process owner to read it. They should recognise the actual inputs, outputs, people and systems. Confirm that links open the intended records and that remaining gaps are explicitly assigned.
The evidence export can help a reviewer inspect the current record. Exporting it does not complete an approval or prove compliance.
If something goes wrong
| Problem | Next action |
|---|---|
| A data category or subject is missing | Create or correct the reusable data record, then link it |
| Readiness remains blocked | Read the specific check; a complete narrative may still lack a required relationship |
| Inherited rights seem inappropriate | Ask the privacy owner to review the source default before overriding it |
| The activity changes materially | Update the source facts and revisit connected assessments and reviews |
Human judgement matters
Backstory organises the evidence; it does not choose a lawful basis or validate a processing purpose for you.
What next?
For the wider context, see Manage privacy records and assessments.
Schedule a review and complete any required assessment. Keep the record current when the activity changes rather than waiting for an annual date.
Get help
Ask your Organisation Administrator about access or the task owner about the content. For a platform error, include this guide reference, the affected page and a sanitised message, not confidential evidence or session details.